CyberRota Analysis
AI-GeneratedThe Twig sandbox mechanism in Craft CMS is improperly configured, allowing authenticated users to execute remote code through dangerous functionalities inherited from the Yii framework. This vulnerability poses a significant risk of unauthorized access and system compromise. Organizations using Craft CMS should prioritize remediation to mitigate potential exploitation.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
The Twig sandbox mechanism in Craft CMS is configured to allow dangerous functionality from the Yii framework, leading to authenticated RCE similar to previously disclosed vulnerabilities.